- 40
- 137 676
Google Workspace Admins
Estonia
เข้าร่วมเมื่อ 8 ธ.ค. 2020
Google Workspace Admins is an IT admin driven series of live and pre-recorded technical talks covering any and all topics that a Google Workspace Admin would find useful. We’ll cover topics that would benefit the Tier 1 IT help desk admin on up to the super admin and the CIO.
Signup to get invited to all future events: forms.gle/7cdaQuvnDGp7PhkV7
Signup to get invited to all future events: forms.gle/7cdaQuvnDGp7PhkV7
Blocking Access from Specific Countries using Context Aware Access
The Google Admin Console settings have changed over the years, but the documentation has not. It is not quite straight forward to set up an access level to exclude certain IP addresses, or countries.
Thankfully it is possible to create an access level using Common Expression Language (CEL) or using Access Context Manager in Google Cloud Platform.
In this video, we look at how to create access levels and apply it to an application using group membership.
Context Aware Access is available on Enterprise Standard or higher, or you can purchase Cloud Identity Premium and assign to users who may require it.
Custom Access Level Spec:
cloud.google.com/access-context-manager/docs/custom-access-level-spec
Outdated Google Support Documentation:
support.google.com/a/answer/9587667?hl=en
A recommended reading (with old screenshots):
hjkimbrian.medium.com/no-brainer-for-every-google-workspace-admin-context-aware-access-c767b6e62ca4
Old video from 2021:
th-cam.com/video/RRE46GJwl88/w-d-xo.html
#googleworkspace #gsuite #security #conditionalaccess
Thankfully it is possible to create an access level using Common Expression Language (CEL) or using Access Context Manager in Google Cloud Platform.
In this video, we look at how to create access levels and apply it to an application using group membership.
Context Aware Access is available on Enterprise Standard or higher, or you can purchase Cloud Identity Premium and assign to users who may require it.
Custom Access Level Spec:
cloud.google.com/access-context-manager/docs/custom-access-level-spec
Outdated Google Support Documentation:
support.google.com/a/answer/9587667?hl=en
A recommended reading (with old screenshots):
hjkimbrian.medium.com/no-brainer-for-every-google-workspace-admin-context-aware-access-c767b6e62ca4
Old video from 2021:
th-cam.com/video/RRE46GJwl88/w-d-xo.html
#googleworkspace #gsuite #security #conditionalaccess
มุมมอง: 76
วีดีโอ
Locking Google Drive Files using Google Apps Manager (GAM7)
มุมมอง 133หลายเดือนก่อน
There may be reasons why you may need to lock Google Drive files in bulk such as when doing a Google to Google migration using mergers or acquisitions. In this video, we review the 2-step process of listing the drive files that are lockable and locking the files so that only the owners or Shared Drive Managers can unlock the files. Link to API Documentation: developers.google.com/drive/api/guid...
Enrolling Chrome Browser for Cloud Management (Chrome Enterprise Core)
มุมมอง 521หลายเดือนก่อน
Chrome Enterprise Core allows you to centrally manage Chrome Browser from the Admin Console regardless of the operating system. In this video, we look at enrolling Chrome Browser on a Windows Server using a registry key. Alternatively, the enrollment token can be pushed using MDM of your choice. Help Center Article: support.google.com/chrome/a/answer/9301891?hl=en List of Chrome Policies: chrom...
Google Drive Inventory - Uploading Google Drive File Information to BigQuery
มุมมอง 176หลายเดือนก่อน
For Google Workspace Enterprise Customers,,Google made Drive Inventory Reporting available to automatically upload file attributes to a BigQuery Dataset. In this video, we look at how to set up the configuration, and how to generate a CSV file using GAM and upload to BigQuery for those who do not have the feature, or those wishing to augment the data that Google provides. Google Workspace Updat...
Google Drive Log Events - Understanding API based actions
มุมมอง 182หลายเดือนก่อน
Earlier this year, Google introduced the ability to see API based actions in Drive Audit Log. With growing popularity of AI based tools such as ChatGPT, users may be uploading potentially sensitive documents directly from Google Drive. If you want to block the users' ability to upload Drive files to ChatGPT, you may want to consider blocking the Client ID for ChatGPT, or changing the setting so...
Using Policy API with Google Apps Manager (GAM7)
มุมมอง 327หลายเดือนก่อน
Google recently released much awaited Policy API in Beta. Developers of GAM (Jay and Ross) have already implemented support for the API. In this video, we take a look at listing the policies in a Google Sheet and take a look at different ways to filter the output to make it more readable. Google Workspace Blog: workspaceupdates.googleblog.com/2024/10/audit-security-settings-policy-api-open-beta...
Upgrading from GAMADV-XTD3 to GAM7
มุมมอง 4323 หลายเดือนก่อน
Jay and Ross have decided to merge GAM and GAMADV-XTD3 to a single project. This video shows the steps involved to upgrade GAMADV-XTD3 to GAM7 github.com/GAM-team/GAM/wiki/GAM7-FAQ github.com/taers232c/GAMADV-XTD3/wiki/How-to-Update-Advanced-GAM-to-GAM7
Listing Spaces, Members, and Messages using Google Chat API using GAMADV-XTD3
มุมมอง 6668 หลายเดือนก่อน
Did you know you can use GAMADV-XTD3 to list Chat Spaces, Members, and Messages today? Sharing a file in a Space, seems to create a drive permission with a group that admins do not have visibility to, which presents challenges for administrators when auditing file permissions on a large scale. See Chat API release notes here: developers.google.com/workspace/chat/docs/release-notes See GAMADV-XT...
Creating Drive Labels and Using with GAMADV-XTD3
มุมมอง 1.1K9 หลายเดือนก่อน
In this video, we look at how you can create Labels for Google Drive and see how it is used in GAMADV-XTD3 with Drive and Drive Labels API. support.google.com/a/answer/9292382?hl=en developers.google.com/drive/labels/guides/overview developers.google.com/drive/api/guides/search-labels 00:00 - Turning on Drive Labels from Admin Console 00:29 - Upcoming changes to Drive Labels 01:13 - Creation of...
Setting up GAMADV-XTD3 on a Google Cloud Platform Compute Engine Securely
มุมมอง 50410 หลายเดือนก่อน
Disclaimer: This video is NOT meant for people setting up GAMADV-XTD3 for the first time. In most organizations, setting it up the normal way should be fine. This video is meant for administrators who have some familiarity with Google Cloud Platform's IAM best practices, as well as strong knowlege of authentication/authorization for GAMADV-XTD3, including domain-wide delegation of authority and...
Using Target Audience in Google Workspace with Google Drive and Calendar
มุมมอง 71710 หลายเดือนก่อน
In this video, we cover what a Target Audience is, how it's created, and how it's used in Google Drive and Calendar. Other than the API documentation, Google's description of how target audience is formulated is a little lacking, which is linked below. Using target audiences could be useful when identifying files that may have been shared with the entire domain when onboarding contractors, etc....
Using Chrome Policies to Help Avoid Chrome Browser Profile Confusion
มุมมอง 1.1Kปีที่แล้ว
One of the biggest challenges that the users face with Google Workspace is ensuring tha they are signed into a correct Google account. By using a Chrome policy, you can ensure that users are only signed into a managed account within a Chrome profile. chromeenterprise.google/policies/#AllowedDomainsForApps support.google.com/a/answer/1668854?hl=en Thank you to everyone who mentioned that the pre...
Copying Folders from My Drive to Shared Drive using Rclone and GAM
มุมมอง 2.4Kปีที่แล้ว
Google recently announed beta feature to allow users to move folders from My Drive to Shared Drive. We at Workspace Admins think that it should still be an activity carried out by the administrators as it may require preliminary assessment with regards to external file ownership, multiparenting. In this video, we look at how we might use Rclone and GAM to take an inventory of the files and copy...
Promoting Domain Alias using GAM
มุมมอง 336ปีที่แล้ว
When a domain is added as a domain alias, re-adding it as a secondary domain will not automatically created the aliases. With some prepration in advance, you can bulk create aliases with minimal disruption to your users. docs.google.com/document/d/1YqXPqVP_Mit_ozsaPDvSOKLO6Xp0Awth3TvXrhM3Zt8/preview Workspace Admins Info View the Google Workspace Admins Public Calendar of upcoming events: calen...
Controlling Access to Third Party Apps in Google Workspace
มุมมอง 6Kปีที่แล้ว
By default, users have the ability to authorize any third party applications that may have access to users' Gmail, Drive, etc. If you have not yet restricted access to the third party apps the steps from a Googler are as follows: 1. Trust applcations users are using 2. Restrict API access (All scopes except for sign-in) 3. Review the applications and remove trust for unauthorized applications W...
Setting up BigQuery Log Export from Google Workspace
มุมมอง 1.8K2 ปีที่แล้ว
Setting up BigQuery Log Export from Google Workspace
Impact of changing username on third party applications (OAuth)
มุมมอง 2822 ปีที่แล้ว
Impact of changing username on third party applications (OAuth)
Setting up Google Marketing Platform Organization and Possible Bug in Google?
มุมมอง 6802 ปีที่แล้ว
Setting up Google Marketing Platform Organization and Possible Bug in Google?
Using AzureAD as Identity Provider for Google Workspace
มุมมอง 27K3 ปีที่แล้ว
Using AzureAD as Identity Provider for Google Workspace
Unmanaged and Conflicting Accounts and using User Invitation API to Invite Users
มุมมอง 9363 ปีที่แล้ว
Unmanaged and Conflicting Accounts and using User Invitation API to Invite Users
Using Apps Script to Automate Shared Drive Access Approval
มุมมอง 2.2K3 ปีที่แล้ว
Using Apps Script to Automate Shared Drive Access Approval
Using Got-Your-Back (GYB) to Back Up and Restore Gmail Messages
มุมมอง 6K3 ปีที่แล้ว
Using Got-Your-Back (GYB) to Back Up and Restore Gmail Messages
Setting up Single Sign-On (SSO) with Third Party Identity Provider (IdP) and Partial SSO
มุมมอง 10K3 ปีที่แล้ว
Setting up Single Sign-On (SSO) with Third Party Identity Provider (IdP) and Partial SSO
Upgrading from Standard to Advanced GAM
มุมมอง 2.3K3 ปีที่แล้ว
Upgrading from Standard to Advanced GAM
Using Rclone to Copy Files from OneDrive to Google Drive
มุมมอง 9K3 ปีที่แล้ว
Using Rclone to Copy Files from OneDrive to Google Drive
Using Python Scripts with GAM/GAMADV-XTD3
มุมมอง 2.8K3 ปีที่แล้ว
Using Python Scripts with GAM/GAMADV-XTD3
Setting Up Calendar Interop between Google and Microsoft
มุมมอง 7K3 ปีที่แล้ว
Setting Up Calendar Interop between Google and Microsoft
Using Google as Identity Provider for Microsoft 365 (SAML SSO)
มุมมอง 14K3 ปีที่แล้ว
Using Google as Identity Provider for Microsoft 365 (SAML SSO)
How to Share Google Resource Calendar Externally
มุมมอง 3.5K3 ปีที่แล้ว
How to Share Google Resource Calendar Externally
Thank you for this guide. Please keep making more
Lifesaver, thank you!!
Just wanted to drop a line to say how much I appreciate the peek behind the curtain. Thank you everyone. Thank you Ross.
Hi, How can you setup calendar interop if users have mailboxes on both Google Workspace and Microsoft 365 that use the same domain for their primary email address? Is it possible without using mail contacts? Thanks in advance!
short answer - you need to use an alias domain in google (e.g. have the exchange users look up availability using google alias - e.g. g.domain.com) if you want to use the same email address, it may be possible but each exchange environment is different and will require advance exchange administration/powershell knowledge which i don't have.
Very cool. I can finally make sure all the tenants I have have the same policies without digging through the console! Thanks for the linked spreadsheet.
Awesome! And thanks for the Template Sheet!
it says -bash: gam: command not found
You need to set your alias for gam. Edit your .bashrc or .zshrc and make sure you have it set to something like this alias gam = '$HOME/bin/gam7/gam' Referencing the gam executable in your gam installation directory.
@WorkspaceAdmins im using windows
In that case you will need to edit your system variable.
Thanks a lot for the video. Now the certificate is about to be expired. Could you please guide on how to renew the certificate on office 365 side? Thank you in advance🙏
We will record a new video soon as Microsoft deprecated PowerShell cmdlet used in the video.
Thank you for this still relevant today.
Can you please explain on how to interpret log reports? How do I troubleshoot emails that were not migrated during the restore?
From what Jay (developer of GYB) said, while some information is written to sqlite database, it's not enough information to troubleshoot a migration. We would recommend using commercial or Google's tools depending on your migration needs
Hi, I'm trying to map Google Groups to Microsoft I don't know what to insert in the App attribute side I tried MemberOf / groups but none of them worked
Thank you for putting this together.
Can I add all external people with access to be a viewer to permissions for a badged label? Assuming it is possible....but how?
Thanks!
Only took Ross like a decade to do this. I had been wondering why they had two versions of the same thing since 2015. And Ross would correct Jay's stuff as well. More Diet cokes for Ross!
Thanks Brian!
This picture is so fuzzy as to be useless...
Sir,can u plz help me with your answer.I am not technical a small business woman,in third party app can I upload my ecommerce template app for my coustomer group and manage its access.plz answer me.I will do that with the help of devloper.
hi admin, i have question, is it using our internet for transfer the files from one drive to google drive?
excellent my brotha!
This was super helpful. Thank you. Would be possible to combine this with a cron job that would update the google sheet on a daily basis?
I just wanted to say thank you for the video. That was very helpful.
GYB is blocked by Google Cloud; GYB aren't validate by Google ("Accès bloqué : GYB n'a pas terminé la procédure de validation de Google"). Then, you must be a tester to have access ("GYB n'a pas terminé la procédure de validation de Google. L'appli est en cours de test, et seuls les testeurs approuvés par le développeur y ont accès. Si vous pensez que vous devriez y avoir accès, contactez le développeur").
This is great info. Has anyone been able to have Google remain the source of truth and have it update AD (or AAD)?
AAD is possible through Google's SCIM. AD is not possible using GCDS or Directory Sync.
Is there a way for individual users to see the free/busy status of users in the other domain when scheduling meetings? (Not resource rooms, user calendars)
Yes, user calendars can be shared with external domain as well
@@WorkspaceAdmins thanks! So same concept as resource room just using the user.csv instead?
Yep, exactly. Or you can pipe the csv as well but you may have to do some filtering in case you have users whose calendars you so not want to share. gam print users | gam csv - gam calendar "~primaryEmail" add acl freebusy domain:acquisition.com
Thanks!!
Hi, thanks for putting this out in open. Few suggestions: 1. Scroll down to the target text rather than using "find" and jump. 2. If you're picking a text from the middle of a list if bullets, take a few seconds to explain why you did that and if others are relevant or not. 3. Break the video into chapters, it will be easier to go back and re-watch a specific topic. This will make the overall experience less overwhelming for first timers.
Thanks for the feedback. This content is NOT meant for first timers setting up GAM. (I will update the video description as such) Happy to answer any questions in groups.google.com/g/google-apps-manager or git.io/gam-chat or by email or here. I make this video in my spare time on a single take usually without script of any kind. But will definitely keep your suggestions in mind for future content.
@@WorkspaceAdminsfair enough :) I'll circle back after reading the wikis, would be a definite help. Thanks for your effort
Thanks Brian!
Will this be able to obfuscate the domain that created the calendar?
Calenar IDs are represented by string@resource.calendar.google.com. The IDs should be random if you are using the new structured resource. Not sure if there are any additional details about the primary domain that might be visible elsewhere though.
Thanks Brian! I didn't know I could use target Audience for Calendar!
Is there a way to disable Microsoft Authenticator now that SAML SSO is working with Google?
you would probably have to do that on Entra ID tenant side for a user, or entire tenant. There is a flag in PowerShell to indicate that the IdP supports MFA, but it doesn't seem to work when Google is the IdP.
I have GYB installed, but where do I download gamadv-xtd3?
github.com/taers232c/GAMADV-XTD3/wiki/Downloads
Great content - tip: edit out your password mistakes
Thanks. No time for editing and account is protected with MFA so no worries there
That really is going to help me. thank you!
Hey mate, thanks for the video. When I click on Authorize I am being prompted to choose a google account and then instead of granting access and test the connectivity I am simply logged into the Google Cloud. Any idea why?
Does your Google account have necessary admin privileges? If you are setting up provisioning, Microsoft will include the scopes that it's requesting in OAuth consent. If your account does not have those, we have seen some odd behaviours.
Is it possible to set this up for only an subset of our users? Like for only a certain OU? We have a main group of users that this would apply to but we want to leave our contractors authenticating via their own Microsoft accounts since they are invted as guests in our Microsoft platform.
Once a domain is federated in Entra ID, all sign in requests for users on that domain will be directed to identity provider (Google). If the guests in your Microsoft tenants are using their own credentials, they should not be affected.
is there a way to force auto-provision users in MS when user login from workspace?
Hi, Would it be possible to show/tell us if there is any specific configurations for room mailbox?
would this calendar share be target to specific organization?
I have bourght it to live recently and it helped me to use Endpoint Token OAuth2 v2. Not v1.
Hi I am getting a lot of these errors after the provisioning is setup (download list) Error Code 45003 - StatusCode: 400 : Bad Request : { error :{ code : Request_BadRequest message : Invalid value specified for property 'mobilePhone' of resource 'User'. details :[{ code : InvalidLength message : The mobilePhone should be between 1 and 64 characters. target : mobilePhone }] innerError :{ date : 2023-10-12T01:19:35 request-id : client-request-id : }}} Not sure why as mobile phone is not a required field. It is the same with the jobtitle field as well. Why is it saying the mobileField should be between 1 and 64 characters?
How to slove this problem :AADSTS5000811: Unable to verify token signature. The signing key identifier does not match any valid registered keys. When I try to configure Google Workspace authentication into Office 365 (SAML)!
hello, how can we remove organisation admin ? is there a way to do it ?
but they could still access google drive from the web right?
How about the other way around?
th-cam.com/video/LjsVO7ApYJ4/w-d-xo.html this video explains the process.
can you have two gcpw work account, from two different domains, on a single PC?
Is there a similar way to do the opposite thing? I have a secondary domain I want to change into an alias. I have tested it manually, I guess what I need to do is to remove all users' aliases temporarily, remove the secondary domain and add it back as an alias. Then add all the aliases back.
How to you deal with new users being added to Google. I cannot add ImmutableID once the domain is federated?
you can try to rollback first command Set-MsolDomainAuthentication -DomainName <your domain name> -Authentication managed
Can we use vice versa
Do you know how to require 2fa everytime you log into windows with GCPW?